From 1dccaf37b075ebfb726d407b9c4d95fcf2983135 Mon Sep 17 00:00:00 2001 From: Ivan Nardi <12729895+IvanNardi@users.noreply.github.com> Date: Tue, 11 Feb 2025 15:48:53 +0100 Subject: DNS: fix check for DGA domain (#2716) If we have a (potential) valid sub-classification, we shoudn't check for DGA, even if the subclassification itself is disabled! --- src/lib/protocols/netbios.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'src/lib/protocols/netbios.c') diff --git a/src/lib/protocols/netbios.c b/src/lib/protocols/netbios.c index fc53563d3..648134b53 100644 --- a/src/lib/protocols/netbios.c +++ b/src/lib/protocols/netbios.c @@ -105,7 +105,7 @@ static void ndpi_int_netbios_add_connection(struct ndpi_detection_module_struct (u_int)(packet->payload_packet_len - off), name, sizeof(name)-1) > 0) { ndpi_hostname_sni_set(flow, (const u_int8_t *)name, strlen((char *)name), NDPI_HOSTNAME_NORM_ALL); - ndpi_check_dga_name(ndpi_struct, flow, flow->host_server_name, 1, 1); + ndpi_check_dga_name(ndpi_struct, flow, flow->host_server_name, 1, 1, 0); } if(sub_protocol == NDPI_PROTOCOL_UNKNOWN) -- cgit v1.2.3